Skip to main content
Category: Privacy Regulations

Extraterritorial Scope

Also known as: Extraterritorial Reach, Extraterritorial Application, Territorial Scope
Simply put

Extraterritorial scope describes how a law can apply to organizations located outside the country or region that enacted it. For example, some data protection rules can reach a company based abroad if it handles the personal data of people located within the regulating jurisdiction. Being subject to such a law and being able to enforce it in practice are two different matters.

Formal definition

Extraterritorial scope refers to the legal reach of a regulation over controllers or processors established outside the enacting jurisdiction, based on connecting factors defined in the instrument itself. Under the EU GDPR, Article 3 sets out territorial scope, applying the Regulation to processing carried out in the context of the activities of an establishment of a controller or processor in the Union; the EDPB has separately examined the practical extent to which the GDPR can be enforced against actors outside the EU, indicating that reach and effective enforcement are distinct questions. Other instruments define their own scope on their own terms and are not interchangeable with the GDPR: the EU AI Act sets its scope in Article 2, covering actors inside and outside the EU, and US instruments addressing extraterritorial access to data operate under separate legal frameworks. This entry defines the concept of extraterritorial reach only; it does not cover the full application criteria of Article 3, the designation of a representative, cross-border transfer mechanics, retention rules, or the mechanics and outcomes of enforcement, which are governed separately and vary by jurisdiction.

Why it matters

Extraterritorial scope matters because an organization's physical location no longer determines which data protection laws it must consider. A company headquartered outside the European Union may still fall within the reach of the EU GDPR where its processing occurs in the context of the activities of an establishment in the Union, as set out in Article 3. This means that compliance planning cannot rely solely on where servers, offices, or legal entities sit; it must account for the connecting factors that each instrument defines for itself.

Crucially, being subject to a law and having that law effectively enforced against you are distinct questions. The European Data Protection Board has separately examined the extent to which the GDPR can be effectively enforced by data protection authorities against actors outside the EU, which underscores that legal reach and practical enforcement do not automatically coincide. Organizations should not treat limited enforcement reach as a safe harbor, nor assume that falling outside a law's practical enforcement means falling outside its scope; the two assessments serve different purposes.

The concept also cuts across multiple, non-interchangeable regimes. The EU AI Act defines its own scope in Article 2, covering actors both inside and outside the EU, and US instruments addressing extraterritorial access to data operate under separate legal frameworks entirely. Treating one instrument's scope rules as a proxy for another's is a common and consequential error, because each defines its territorial reach on its own terms.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads at organizations outside the enacting jurisdiction need to assess whether their processing activities bring them within the reach of instruments such as the EU GDPR under Article 3. They should evaluate scope against the connecting factors each instrument defines, rather than assuming that a foreign location places their organization out of scope.
Legal and Compliance Counsel
Counsel advising multinational organizations must analyze each applicable instrument on its own terms, recognizing that the GDPR, the EU AI Act, and US frameworks addressing extraterritorial access to data are not interchangeable. They also need to distinguish the question of legal reach from the practical question of enforcement, which the EDPB has treated as a separate matter.
AI Governance and Product Teams
Teams building or deploying AI systems that may serve EU users should consider the EU AI Act's scope under Article 2, which encompasses actors both within and outside the EU. This scope analysis is distinct from GDPR territorial scope and should not be conflated with it.
Executives and Board-Level Decision-Makers
Leaders responsible for accountability need to understand that an organization can fall within a foreign law's scope regardless of where it is established, and that limited practical enforcement reach does not equate to being outside that scope. Governance decisions should reflect demonstrable assessment of applicable reach rather than assumptions based on physical location alone.

Inside Extraterritorial Scope

Territorial vs. Extraterritorial Reach
Extraterritorial scope refers to the application of a data protection law to organizations located outside the jurisdiction that enacted it. Under the EU GDPR, for example, the law can apply to controllers or processors not established in the EU when their processing relates to offering goods or services to individuals in the EU or monitoring their behavior in the EU. The precise triggers differ between the EU GDPR and the UK GDPR, and other regimes such as the CCPA and CPRA use different thresholds based on business criteria rather than establishment.
Establishment-Based Application
One basis for scope is whether an organization has an establishment in the jurisdiction, with processing carried out in the context of that establishment's activities. This basis can apply regardless of where the actual processing physically occurs. It is distinct from the targeting-based triggers and typically applies to both controllers and processors, though the specific obligations that follow differ by role.
Targeting and Monitoring Triggers
Where an organization has no establishment in the jurisdiction, extraterritorial application generally turns on whether it targets individuals in that jurisdiction (offering goods or services to them) or monitors their behavior there. Mere accessibility of a website is generally not sufficient on its own; intent to target is typically assessed from surrounding factors. Treatment varies between regimes, so the EU GDPR analysis should not be assumed identical to the UK GDPR or other laws.
Representative Obligations
Some regimes require organizations caught by extraterritorial scope, but without an establishment in the jurisdiction, to designate a local representative. This is a governance and accountability mechanism and is distinct from a data protection officer role. The precise conditions and exemptions differ by regime and are not addressed exhaustively here.
Role-Specific Accountability
Extraterritorial scope does not erase the controller/processor distinction. A controller determines purposes and means of processing and bears the primary accountability obligations, while a processor acts on the controller's documented instructions. Both may fall within extraterritorial scope, but the obligations attaching to each differ and must be assessed separately.

Common questions

Answers to the questions practitioners most commonly ask about Extraterritorial Scope.

Does being outside the EU or UK mean the GDPR does not apply to my organization?
No. Location outside the EU or UK does not, by itself, exclude an organization from scope. The EU GDPR and UK GDPR can apply to controllers or processors established elsewhere where processing relates to offering goods or services to individuals in the relevant territory, or to monitoring their behavior in that territory. Establishment is one basis for application, but the targeting and monitoring criteria mean that a foreign-established entity may still fall within scope. This answer addresses the trigger concept only and does not cover appointing a representative, cross-border transfer mechanics, or enforcement outcomes, which are treated separately.
Does the extraterritorial reach of the EU GDPR mean other regimes like the UK GDPR, CCPA and CPRA, or HIPAA all apply the same way?
No. Extraterritorial or extra-jurisdictional application is not uniform across regimes, and the instruments are not interchangeable. The EU GDPR and UK GDPR each define their own territorial scope for their respective territories, and the CCPA and CPRA use their own thresholds and defined terms for businesses handling information about relevant consumers. HIPAA, ISO/IEC 27701, and the NIST Privacy Framework are framed differently again and should not be assumed to mirror GDPR-style targeting or monitoring tests. Each regime must be assessed against its own text; concluding scope under one instrument does not determine scope under another.
How do we assess whether our processing falls within the extraterritorial scope of a given regime?
Generally, start by identifying the specific instrument in question and applying its own scope criteria rather than a generic test. For the EU GDPR or UK GDPR this typically involves examining whether you are established in the territory, whether you offer goods or services to individuals there, and whether you monitor their behavior in that territory, assessed against the facts of your activities. For the CCPA and CPRA, assess against that regime's defined thresholds and terms. Document the analysis and the factual basis for each conclusion. This is a scoping assessment only and does not address downstream obligations such as representatives, transfers, or retention.
What evidence should we retain to demonstrate our extraterritorial scope determination?
Under accountability-oriented frameworks, a stated conclusion is generally insufficient; demonstrable evidence is expected. Typically this means retaining the documented analysis of which instruments were considered, the factual inputs used, and the reasoning that led to your scope determination for each regime, along with the date and owner of the assessment. Keeping this current as activities change supports a defensible position. This entry does not prescribe a specific retention period or a particular tooling approach, and maintaining such records is distinct from any records of processing activities obligation, which serves a different purpose.
If we are established in one jurisdiction but our processor operates elsewhere, whose obligations does extraterritorial scope affect?
Scope is generally assessed separately for controllers and processors, and each may be brought within a regime's reach on its own facts. A controller established in one place does not automatically transfer or absorb the scope analysis for its processor located elsewhere; the processor's activities are examined against the applicable instrument's criteria in their own right. Obligations then attach to each party according to its role. This answer covers the scoping question only and does not address the allocation of specific obligations, contractual terms between the parties, or cross-border transfer requirements.
Does concluding we are in scope of a regime tell us which specific obligations we owe?
No. Determining that an organization falls within the extraterritorial scope of an instrument is a threshold conclusion; it establishes that the regime applies but does not itself specify the substantive obligations, whether a representative must be appointed, how transfers must be handled, or what retention and impact-assessment steps are required. Those obligations depend on your role, the nature of the processing, and the instrument's detailed provisions, and must be worked through separately. This entry addresses scope alone and leaves the resulting obligations out of its coverage.

Common misconceptions

If an organization has no offices, servers, or staff in a jurisdiction, that jurisdiction's data protection law cannot apply to it.
Physical presence is only one basis for application. Under regimes such as the EU GDPR, targeting individuals in the jurisdiction or monitoring their behavior there can bring an organization within scope even with no local establishment. The analysis depends on the specific regime and its triggers, which are not interchangeable across the EU GDPR, UK GDPR, and CCPA/CPRA.
Making a website accessible to people in another jurisdiction automatically subjects the operator to that jurisdiction's law.
Mere accessibility is generally not sufficient on its own. Extraterritorial application typically requires evidence of intent to target individuals in the jurisdiction or of behavioral monitoring, assessed from surrounding factors. The threshold and factors vary by regime, and this entry does not cover how any specific authority weighs those factors.
Appointing a local representative or designating a DPO resolves all extraterritorial obligations.
A representative requirement, where it applies, is one accountability mechanism and is distinct from the data protection officer role, which addresses different functions. Designating either does not by itself satisfy the substantive obligations that flow from being in scope, and requirements differ by regime and by whether the organization acts as controller or processor.

Best practices

Map processing activities against the specific triggers of each relevant regime separately, distinguishing establishment-based application from targeting and monitoring triggers, rather than assuming the EU GDPR, UK GDPR, and CCPA/CPRA apply on the same terms.
Assess targeting intent using surrounding factors rather than relying on website accessibility alone, and document the reasoning so the scope determination is demonstrable rather than merely asserted.
Analyze extraterritorial scope separately for each role, identifying whether the organization acts as controller or processor for a given processing activity, since the obligations that follow differ by role.
Where a regime requires a local representative for organizations without an establishment, confirm the conditions and treat that designation as distinct from any data protection officer function rather than a substitute for it.
Maintain evidence supporting scope determinations, because accountability under governance frameworks generally requires demonstrable documentation, not stated intent alone.
Recognize that this scope analysis does not resolve cross-border transfer mechanics, retention rules, or enforcement outcomes, and address those as separate workstreams with regime-specific advice where needed.